2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3164HIGH8.8ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permis...
CVE-2021-3152MEDIUM5.3Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks aga...
CVE-2021-3115HIGH7.5Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when ...
CVE-2021-3114MEDIUM6.5In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an und...
CVE-2021-26267HIGH7.5cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
CVE-2021-26266HIGH7.5cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
CVE-2021-26026HIGH7.8PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS...
CVE-2021-26025HIGH7.8PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS...
CVE-2021-25908HIGH7.5An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.
CVE-2021-25907CRITICAL9.8An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} do...
CVE-2021-25906HIGH7.5An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a dou...
CVE-2021-25905CRITICAL9.1An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized mem...
CVE-2021-25904HIGH7.5An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of ...
CVE-2021-25903HIGH7.5An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.
CVE-2021-25902HIGH7.5An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a dou...
CVE-2021-25901MEDIUM5.3An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data r...
CVE-2021-25900CRITICAL9.8An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer ...
CVE-2021-25864HIGH7.5node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil...
CVE-2021-25863HIGH8.8Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
CVE-2021-22873MEDIUM6.1Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg...
CVE-2021-22872MEDIUM6.1Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly acce...
CVE-2021-22871MEDIUM4.8Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL webs...
CVE-2021-22698HIGH7.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody...
CVE-2021-22697HIGH7.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody...
CVE-2021-21723HIGH7.5Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now